Our mission

Security should not wait for a human to notice.

d2defence was founded by security engineers and machine learning researchers who had spent their careers on the wrong side of the alert queue — watching teams triage by hand while attackers moved in seconds.

We build autonomous security agents that close that gap: they detect the threat, decide what actually matters, and defend the estate, with every action logged and reversible.

2021

Founded

7

Products, one Autonomous AI Engine

140+

Engineers and researchers

3

Engineering hubs

01 / How we work

What we hold to.

Four positions that decide what we build and, more often, what we refuse to.

01 / Principle

Autonomy with an audit trail

Agents act on the reversible, well-evidenced cases without waiting for a human. Every autonomous action is logged, attributable, and reversible — autonomy without accountability is just risk.

02 / Principle

Evidence over alerts

An alert is a hypothesis; proof is a finding. We ship products that demonstrate exploitability with verified execution rather than adding another queue for someone to grade.

03 / Principle

One core, not seven silos

A credential flagged in one product should revoke a session in another. Shared context is the whole argument for a platform — otherwise it is just point tools with the same invoice.

04 / Principle

Speed is a security property

Dwell time is the damage. We treat the gap between detection and containment as the number that matters, and we publish it rather than hiding behind feature counts.

02 / Trajectory

How we got here.

2021

Founded

Started by security engineers and ML researchers who had spent years on the wrong side of the alert queue.

2022

First autonomous agent

Shipped the Autonomous AI Engine that correlates endpoint, identity, and secrets telemetry into a single decision.

2024

Unified platform

Seven products consolidated onto one Autonomous AI Engine, with cross-product response replacing disconnected alerts.

2026

Autonomous response

Full detect-decide-defend loop in production, containing well-evidenced incidents without human approval.